US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

Cybersecurity and intelligence agencies in the US, UK, and Netherlands have issued a joint advisory warning of a Windows malware family dubbed Chosen Brick, deployed by Iranian state cyber actors to target dissidents, activists, and journalists worldwide.

Active since at least 2025, Chosen Brick is leveraged by Iranian operators to harvest contacts, emails, social media messages, and other types of data that can be used to track an individual’s location and life patterns.

The agencies noted that the activity directly supports state-sponsored repression against individuals perceived as threats to the regime, with stolen personal information occasionally posted to pro-Iranian leak sites to harass targets.

The attack chain typically begins on messaging platforms such as WhatsApp and Telegram. Operators research their targets to build rapport, often posing as acquaintances or platform technical support representatives before delivering weaponized files.

Attackers frequently initiate contact through a target’s corporate device. However, if security controls...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more